AI analysis
The Botslab G980H dash camera firmware generates session identifiers from a small, sequential value space instead of a cryptographically unpredictable source, making valid session tokens guessable. An unauthenticated attacker with adjacent-network access — in practice, someone within range of the camera's own Wi-Fi hotspot — who knows that an active session exists can determine a valid session ID and hijack that session, bypassing authorization controls. Successful exploitation gives the attacker the same access as the legitimate mobile-app user, including camera control and access to live video and recordings, which is reflected in the high CVSS 4.0 score of 7.7. Only owners of the Botslab G980H model are affected; the advisory data does not enumerate specific vulnerable firmware versions. There is no known public proof-of-concept, no evidence of exploitation in the wild, and the flaw is not on CISA's KEV list.
What to do: Update the G980H to the latest firmware via the Botslab app as soon as the vendor ships a fix, and monitor the ICS-CERT advisory for the patched version since affected versions were not enumerated. Until patched, replace the camera's default Wi-Fi password with a strong unique one, disable the hotspot when not actively in use, and avoid pairing the camera on shared or public networks to shrink the adjacent-network attack window.
Affected
| Botslab G980H dash camera (firmware) | — |
Estimated exposure
moderatelikely tens of thousands of devices globally (single consumer dashcam model; no public sales or install figures) — Estimated from the product being one model from a small consumer dashcam brand, with the practically attackable population further limited to cameras with an active Wi-Fi session at a given moment; no public install counts or scan data…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active session exists could potentially determine a valid session identifier and use it to bypass intended authorization controls.